Skip to content

Rebuild comment sync as a post-merge repair caller - #158

Merged
jeremy merged 1 commit into
mainfrom
ci/post-merge-sync-caller
Jul 27, 2026
Merged

Rebuild comment sync as a post-merge repair caller#158
jeremy merged 1 commit into
mainfrom
ci/post-merge-sync-caller

Conversation

@jeremy

@jeremy jeremy commented Jul 27, 2026

Copy link
Copy Markdown
Member

Replaces the in-PR workflow_run caller with the post-merge model (basecamp/.github#11, pinned 45d3fc95): any non-Dependabot push to a Dependabot branch flips the retriggered runs' actor off dependabot[bot], lifting the Dependabot sandbox for the PR's unreviewed action bumps — verified live on basecamp/basecamp-cli#566. Post-merge, the reusable workflow repairs drifted comments via a comment-only auto-merging PR; every pin it touches is already reviewed, and nothing is ever pushed to a Dependabot branch. Dependabot maintains the bare comments on its own PRs after the bare-pin restructure (Layer 1, merged fleet-wide).

The workflow entry stays disabled through this merge; repos are enabled one at a time after a full-cycle exercise (seeded drift → repair PR → held-run approval → CI → auto-merge → terminal no-op) in one repo.

Replaces the in-PR workflow_run caller: any non-Dependabot push to a
Dependabot branch flips the retriggered runs' actor off dependabot[bot],
lifting the Dependabot sandbox for the PR's unreviewed action bumps
(verified live on basecamp-cli#566; see basecamp/.github#11). The
reusable workflow now runs post-merge: on workflow-file pushes to the
default branch it repairs drifted comments via a comment-only
auto-merging PR — only reviewed code ever executes. Dependabot itself
maintains the bare comments on its own PRs after the bare-pin
restructure. Lands disabled; enabled per repo after a full-cycle
exercise.
Copilot AI review requested due to automatic review settings July 27, 2026 21:31
@github-actions github-actions Bot added the ci label Jul 27, 2026
@jeremy
jeremy merged commit 3a49166 into main Jul 27, 2026
18 checks passed
@jeremy
jeremy deleted the ci/post-merge-sync-caller branch July 27, 2026 21:34

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR refactors the repo’s Dependabot action-pin comment synchronization workflow to stop running in-PR logic and instead delegate to a SHA-pinned reusable workflow intended to run post-merge on main, opening an auto-merge “comment-only” repair PR when drift is detected.

Changes:

  • Replaces the previous workflow_run-driven in-repo implementation with a reusable workflow call pinned to basecamp/.github commit 45d3fc95….
  • Switches the trigger to push on main (workflow-file path filtered) plus manual workflow_dispatch.
  • Uses secrets: inherit and job-level token permissions for the reusable workflow’s PR/Actions operations.

Tip

If you aren't ready for review, convert to a draft PR.
Click "Convert to draft" or run gh pr ready --undo.
Click "Ready for review" or run gh pr ready to reengage.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread .github/workflows/dependabot-sync-actions-comments.yml
Comment thread .github/workflows/dependabot-sync-actions-comments.yml
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants